> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# ISMS Fundamentals

> How risk management and compliance fit together, and what the ISMS tab on an asset connects.

ISMS covers two tasks in Docusnap365: managing risks and demonstrating that
your organization meets its laws and standards. Both areas use the same ISMS
data on the asset.

## Risk management and compliance

<CardGroup cols={2}>
  <Card title="Risk Management" icon="shield-halved">
    Build risks from threats and vulnerabilities, assess them, and treat them
    with controls.
  </Card>

  <Card title="Compliance" icon="clipboard-check">
    Activate regulations and assess their objectives individually.
  </Card>
</CardGroup>

Both areas list a *Dashboard* as their first entry — two different pages with
the same name, one for risk metrics, one for how far activated regulations
are met.

[Risk Management Fundamentals](/docs/en/isms/understanding-risk-management) and
[Understanding Compliance](/docs/en/isms/understanding-compliance) cover both areas
in depth.

## Protection need on the asset

Independent of the ISMS menu, assets carry their own *ISMS* tab on their
detail page: the protection need across the three security objectives, plus
a responsible person.

| Security objective | Meaning |
| - | - |
| *Confidentiality* | protection against unauthorized disclosure |
| *Integrity* | protection against unnoticed alteration |
| *Availability* | protection against outage and data loss |

The *Total Protection Need* is the highest of the three individual levels
(Maximum Principle). A security objective with no value counts as *Normal*
and does not raise the maximum.

<Note>
  The *ISMS* tab belongs to the asset, not to the ISMS menu: it appears on the
  asset's detail page, not under *ISMS › Risk Management*.
</Note>

## Threats, vulnerabilities, and regulations

You create threats by hand or take them from the *Threat Catalog*. You create
vulnerabilities by hand. Which regulations apply is something you activate
under Compliance.

Risks, controls, threats, and vulnerabilities are linked to each other and to
assets through relations; the risk is always the source of the relation.

## Limits

The risk matrix's edge length and zone thresholds come from the global
settings and apply tenant-wide — without a custom setting, a 5×5 grid
applies. Two tenants with different settings can rate the same risk
assessment differently. You set the matrix size under
[Settings](/docs/en/settings/isms-settings).

## Related

[Determine Protection Needs](/docs/en/isms/protection-needs) and
[Create and Assess Risks](/docs/en/isms/assess-risks) cover risk management in
depth. The quickest entry point needs neither an asset nor a scan:
[Assessing NIS-2](/docs/en/getting-started/nis2).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.